Right.
For (and from) all the newbies out there who want help for studying, there have been numerous questions about, well, questions. As in, "what's the best set of practice questions to use while studying for the exam?"
The answer is, none of them.
I have looked at an awful lot of practice question sets, and they are uniformly awful. Most try to be "hard" by bringing in trivia: that is not representative of the exam. Most concentrate on a bunch of facts: that is not representative of the exam.
So, from my own stash, collected and developed over the decades, I'm going to give you some samples that do represent the types of questions that you will probably see on the exam. Note that none of these questions will appear on the exam. You can't pass the CISSP exam by memorizing a brain dump. These will just give you a feel.
For each question I'll give the answer, what type of question this represents, and possibly ways to approach this type of question.
I'll be doing this over time, "replying" to this post to add questions. Others are free to add sample questions if they wish, but be ready to be (possibly severely) critiqued.
Data dictionaries are specific to the data field as length, type, required etc. This is a good description of data dictionaries https://www.bridging-the-gap.com/data-dictionary/
Oh, and, just to make sure that you know, "blockchain" is not the answer.
Unless the question is "stupidest 'magic security technology' buzzphrase in the last decade."
I would like to thank you for your great effort, I have one question, why do you consider role-based access control as discretionary access control.
Sybex and other references consider role-based access control and rule-based access control as non-discretionary access control.
Can you elaborate this more?
Thanks again, Your questions and answers are really helpful.
Thanks Again, I am also confused here one more time,
Sybex and other references consider role-based access control and rule-based access control as non-discretionary access control.
Can you clear this for me a little more
I do appreciate your effort.
Thanks,
think of it this way - you are "tagged" with a role i.e. domain admin. If the user is placed in a role or rule based control for domain admin - you as the user have no say it it - therefore non-discretionary.
Would agree - the key is the interface - think of this as what is truly an interface - forward facing - watch the answers
Thanks for taking the time to post sample questions.
I had taken many practice tests but was still unsure if I was ready to take the exam. I was wrong on several of the sample questions but, I gained the confidence that I understood the principals and decided to take the exam.
I found the advice in your explanations was helpful. I did come across one question that gave a definition and I had my understanding of the word. But when I looked at the answers, I hadn’t seen any of them mentioned before in my studies. It gave me a slight chuckle when I thought " just because you don't know it, doesn't make it the right answer." I was stuck choosing an answer I didn’t know.
To add something to this thread, I would say that the above statement and think of “initial steps” probably got me a couple of right answers.